Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3085▲ 506 respecto a la semana anterior
Críticas / altas1460▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
5122 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.52% | — | Dataprobe Iboot-pdu4-n20 FirmwareDataprobe Iboot-pdu4sa-n15 FirmwareDataprobe Iboot-pdu4a-n15 FirmwareDataprobe Iboot-pdu4sa-n20 Firmware+18 | 22/5/2023 | 17/6/2026 | A proprietary protocol for iBoot devices is used for control and keepalive commands. The function compares the username and password; it also contains the configuration data for the user specified. If the user does not exist, then it sends a value for username and password, which allows successful authentication for a… | |
| Modificada | Crítica (9.8) | 0.58% | — | Dataprobe Iboot-pdu4-n20 FirmwareDataprobe Iboot-pdu4sa-n15 FirmwareDataprobe Iboot-pdu4a-n15 FirmwareDataprobe Iboot-pdu4sa-n20 Firmware+18 | 22/5/2023 | 17/6/2026 | The affected product exposes multiple sensitive data fields of the affected product. An attacker can use the SNMP command to get device mac address and login as admin. | |
| Modificada | Crítica (9.8) | 1.2% | — | Dataprobe Iboot-pdu4-n20 FirmwareDataprobe Iboot-pdu4sa-n15 FirmwareDataprobe Iboot-pdu4a-n15 FirmwareDataprobe Iboot-pdu4sa-n20 Firmware+18 | 22/5/2023 | 17/6/2026 | The affected product is vulnerable to a stack-based buffer overflow which could lead to a denial of service or remote code execution. | |
| Modificada | Media (6.5) | 0.17% | — | Dataprobe Iboot-pdu4-n20 FirmwareDataprobe Iboot-pdu4sa-n15 FirmwareDataprobe Iboot-pdu4a-n15 FirmwareDataprobe Iboot-pdu4sa-n20 Firmware+18 | 22/5/2023 | 17/6/2026 | The Dataprobe cloud usernames and passwords are stored in plain text in a specific file. Any user able to read this specific file from the device could compromise other devices connected to the user's cloud. | |
| Modificada | Media (6.5) | 0.52% | — | Johnsoncontrols Openblue Enterprise Manager Data Collector | 18/5/2023 | 17/6/2026 | OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances. | |
| Modificada | Alta (7.5) | 1.1% | 💥 PoC | Johnsoncontrols Openblue Enterprise Manager Data Collector | 18/5/2023 | 17/6/2026 | Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances. | |
| Modificada | Crítica (9.1) | 0.75% | — | Vmware Greenplum Database | 15/5/2023 | 17/6/2026 | Greenplum Database (GPDB) is an open source data warehouse based on PostgreSQL. In versions prior to 6.22.3 Greenplum Database used an unsafe methods to extract tar files within GPPKGs. greenplum-db is vulnerable to path traversal leading to arbitrary file writes. An attacker can use this vulnerability to overwrite… | |
| Modificada | Alta (7.8) | 0.21% | — | Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+25 | 10/5/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.20% | — | Intel Data Center Manager | 10/5/2023 | 17/6/2026 | Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 0.55% | — | Intel Data Center Manager | 10/5/2023 | 17/6/2026 | Improper authentication in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via network access. | |
| Modificada | Alta (7.8) | 0.17% | — | Intel Data Center Manager | 10/5/2023 | 17/6/2026 | Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.17% | — | Intel Data Center Manager | 10/5/2023 | 17/6/2026 | Uncontrolled search path in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 0.59% | — | Intel Data Center Manager | 10/5/2023 | 17/6/2026 | Protection mechanism failure in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via network access. | |
| Modificada | Media (6.5) | 0.53% | — | Intel Data Center Manager | 10/5/2023 | 17/6/2026 | Insufficiently protected credentials in the Intel(R) DCM software before version 5.0.1 may allow an authenticated user to potentially enable information disclosure via network access. | |
| Modificada | Alta (7.8) | 0.20% | — | Intel Data Center Manager | 10/5/2023 | 17/6/2026 | Exposure of data element to wrong session in the Intel DCM software before version 5.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.1) | 0.85% | 💥 Exploit | Membership Database Project Membership Database | 8/5/2023 | 17/6/2026 | The Membership Database WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Alta (7.5) | 0.44% | — | IBM Qradar Data Synchronization | 6/5/2023 | 17/6/2026 | IBM QRadar Data Synchronization App 1.0 through 3.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 217370. | |
| Modificada | Media (5.4) | 0.39% | — | Tms-outsource Wpdatatables | 3/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TMS-Plugins wpDataTables plugin <= 2.1.49 versions. | |
| Modificada | Media (5.3) | 0.79% | — | Atlassian Confluence Data CenterAtlassian Confluence Server | 1/5/2023 | 17/6/2026 | Affected versions of Atlassian Confluence Server and Data Center allow anonymous remote attackers to view the names of attachments and labels in a private Confluence space. This occurs via an Information Disclosure vulnerability in the macro preview feature. This vulnerability was reported by Rojan Rijal of the Tinder… | |
| Modificada | Media (6.5) | 0.40% | — | IBM Watson Machine Learning ON Cloud PAK FOR Data | 27/4/2023 | 17/6/2026 | IBM Watson Machine Learning on Cloud Pak for Data 4.0 and 4.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 253350. | |
| Modificada | Crítica (9.8) | 1.1% | — | Gajshield Data Security Firewall Firmware | 27/4/2023 | 17/6/2026 | This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 (except v4.21) due to insecure default credentials which allows remote attacker to login as superuser by using default username/password via web-based management interface and/or exposed SSH port thereby enabling remote… | |
| Modificada | Alta (7.2) | 0.87% | — | IBM Cloud PAK FOR Data | 26/4/2023 | 17/6/2026 | IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 232034. | |
| Modificada | Media (6.5) | 1.3% | — | Solarwinds Database Performance Analyzer | 25/4/2023 | 17/6/2026 | Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server. | |
| Modificada | Alta (7.5) | 0.81% | — | Solarwinds Database Performance Analyzer | 25/4/2023 | 17/6/2026 | No exception handling vulnerability which revealed sensitive or excessive information to users. | |
| Modificada | Alta (7.8) | 0.24% | — | Datakit Crosscadware | 20/4/2023 | 17/6/2026 | Datakit CrossCadWare_x64.dll contains an out-of-bounds write past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This could allow an attacker to execute code in the context of the current process. |